git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/3] Add support for per-remote and per-namespace SSH options

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Mar 27, 2026, 22:06 UTC
Message-ID
<acb_SQ8gdy-fQaFj@fruit.crustytoothpaste.net>
In-Reply-To
<09c5fe7d-8379-4f68-bf1c-9869e2924cb8@opperschaap.net>
On 2026-03-27 at 16:49:35, Wesley wrote:
Show 15 quoted lines
> On 3/27/26 12:10, Junio C Hamano wrote:
> 
> > I somehow thought that this practice is so widespread that it was
> > one of the few first things any new people learn to do, but perhaps
> > we do not have a good documentation coverage?
> 
> As said before it is weird thing to configure a global ssh configuration
> just for git transport. It doesn't make much sense.
> 
> The problem with ssh_config usage is that you need to change your ssh
> config, which is machine global, not just git. And not portable across teams
> with configurations committed to git. Myrepos is a good example of this. My
> former employer had this and I know the Perl metacpan project also uses
> mysrepos. Changing every URL dynamically in committed configs isn't really a
> nice ask.

You can also use the conditional inclusion functionality to rewrite URLs for repositories in a certain directory with `url.<URL>.insteadOf`. Or you can use conditional inclusion to use `core.sshCommand` with the `-i` option set appropriately.

Show 9 quoted lines
> The alternative is using core.sshCommand to inject the correct keys, but you
> must apply logic there when you have multiple accounts or forges. Which is
> what I initially did with a zsh-scripts.
> Which is why I ported that logic to git itself, I thought it would be
> beneficial to have an easy way to maintain sshIdentityFile settings.
> 
> In addition, for core.sshCommand to work you must use the full openssh
> command rather than just adding some options to it. Which is an added
> benefit of the proposed changes.

Right, but the additional burden is typing "ssh -i" for that option. That's not very substantial. And the existing option is much more flexible as well, since it allows you to use other options, such as `-o ControlMaster`, which is useful when you're using a security key and don't want to re-authenticate all the time. It also allows you to use arbitrary shell scripting, too, which means that you can customize the configuration depending on what keys are available or what machine you're on (or really anything else).

-- 
brian m. carlson (they/them)
Toronto, Ontario, CA
Previous: WesleyNext: Wesley
Message 18 of 24 in “Add support for per-remote and per-namespace SSH options”
  1. 0/3 Add support for per-remote and per-namespace SSH optionsWesley Schwengle, Mar 26, 2026
  2. 1/3 connect: Rename name to command in connect_git()Wesley Schwengle, Mar 26, 2026
  3. Jeff KingMar 27, 2026
  4. WesleyMar 28, 2026
  5. Jeff KingMar 28, 2026
  6. WesleyMar 28, 2026
  7. 2/3 connect: Add transport->remote->name to git_connect()Wesley Schwengle, Mar 26, 2026
  8. Jeff KingMar 27, 2026
  9. 3/3 connect: Add support for per-remote and per-namespace SSH optionsWesley Schwengle, Mar 26, 2026
  10. Jeff KingMar 27, 2026
  11. WesleyMar 28, 2026
  12. Jeff KingMar 28, 2026
  13. WesleyMar 28, 2026
  14. Johannes SixtMar 27, 2026
  15. WesleyMar 27, 2026
  16. Junio C HamanoMar 27, 2026
  17. WesleyMar 27, 2026
  18. brian m. carlsonMar 27, 2026
  19. WesleyMar 28, 2026
  20. Johannes SixtMar 28, 2026
  21. WesleyMar 28, 2026
  22. Ben KnobleMar 29, 2026
  23. brian m. carlsonMar 27, 2026
  24. Junio C HamanoMar 27, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.